Description
A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by sending specially crafted retryable write commands. The crash state is durably persisted, causing the server process to repeatedly crash on restart and potentially propagating to additional nodes in a sharded cluster. Manual intervention is required to restore service availability.
Published: 2026-09-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an assertion failure in MongoDB Server that can be triggered by an authenticated user with write privileges by sending crafted retryable write commands. This causes a fatal crash that is persisted, making the server repeatedly crash on restart. The result is a denial of service that can spread to other nodes in a sharded cluster.

Affected Systems

MongoDB Server is affected. Version details were not specified in the advisory, so all deployments running MongoDB Server that support retryable writes are potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high impact. Because the attack requires authenticated write access, the attack vector is internal. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation. However, the persistent crash can be destructive, so the risk remains significant if credentials are compromised.

Generated by OpenCVE AI on September 8, 2026 at 19:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest MongoDB release that fixes the assertion failure associated with CWE-617.
  • Restrict write privileges and enforce least privilege for clients that can issue retryable writes, reducing the attack surface for the CWE-617 vulnerability.
  • Monitor server logs for assertion failures; isolate affected nodes manually and ensure backup and failover configurations are in place to recover service, addressing the denial-of-service impact of the CWE-617 flaw.

Generated by OpenCVE AI on September 8, 2026 at 19:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:-:*:*:*
Vendors & Products Mongodb mongodb

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by sending specially crafted retryable write commands. The crash state is durably persisted, causing the server process to repeatedly crash on restart and potentially propagating to additional nodes in a sharded cluster. Manual intervention is required to restore service availability.
Title Persistent Fatal Assertion Crash in MongoDB Server via Crafted Retryable Write Commands Leads to Denial of Service
Weaknesses CWE-617
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-08T17:53:59.910Z

Reserved: 2026-08-27T22:53:09.014Z

Link: CVE-2026-82068

cve-icon Vulnrichment

Updated: 2026-09-08T17:53:57.248Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:35.750

Modified: 2026-09-16T20:38:17.227

Link: CVE-2026-82068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T19:15:16Z

Weaknesses